Data Processing Addendum.
This Data Processing Addendum forms part of the subscription agreement between Sabee Cloud OU and every Sabee customer, and governs how Sabee processes guest personal data on the customer's behalf under GDPR Article 28. Last updated 15 May 2026.
On this page
- 1. Parties
- 2. Subject-matter, duration and nature
- 3. Types of personal data
- 4. Categories of data subjects
- 5. Controller obligations
- 6. Processor obligations (Art 28)
- 7. Controller instructions
- 8. Confidentiality
- 9. Security measures
- 10. Sub-processors
- 11. Assistance with data subject requests
- 12. Personal data breach notification
- 13. DPIA assistance
- 14. International transfers
- 15. Return and deletion of data
- 16. Audit rights
- 17. Liability
- 18. Term
- 19. Governing law
- 20. Contact
- Annex I — Processing details
- Annex II — Technical and organisational measures
- Annex III — Sub-processors
1. Parties
This Data Processing Addendum ("DPA") is entered into between Sabee Cloud OU, a private limited company registered in Estonia under number 14975208, VAT identifier EE102948371, registered office Rotermanni 8, 10111 Tallinn, Estonia ("Processor" or "Sabee"), and the customer entity identified in the underlying subscription agreement or order form ("Controller"). This DPA supplements and forms part of the Sabee Terms of Service. Where this DPA conflicts with the Terms on a matter of personal data processing, this DPA prevails.
2. Subject-matter, duration and nature of the processing
The subject-matter of the processing is the operation of the Sabee platform for the Controller's benefit, including reservation management, channel management, direct booking, revenue analytics, accounting, housekeeping, guest CRM, messaging and multi-property services. The nature of the processing includes collection, storage, organisation, retrieval, use, transmission, and eventual deletion of personal data, carried out by automated means through the Platform's software. The duration of the processing matches the term of the underlying subscription, plus the limited retrieval and deletion period described in Section 15.
3. Types of personal data
Categories of personal data processed on the Controller's behalf include: guest full name and title; contact details (email address, phone number); postal and billing address; identification numbers such as passport or national ID number where captured by the Controller for statutory hotel-registration purposes; date of birth where required for age verification; stay history and folio records; stated preferences, dietary notes and accessibility requirements; communication records between the Controller and the guest routed through the Platform; payment tokens (Sabee never receives or stores raw card numbers — only tokens returned by the integrated payment service provider); and account credentials and usage logs belonging to the Controller's own staff who use the Platform. Full detail is set out in Annex I.
4. Categories of data subjects
Data subjects whose personal data may be processed under this DPA include: guests of the Controller's properties, past, current and prospective; corporate and travel-agency contacts associated with group or corporate bookings; and the Controller's own employees, contractors and other authorised Users of the Platform.
5. Controller obligations
The Controller warrants that it has a valid lawful basis under GDPR Article 6 (and Article 9 where special category data is involved) for all personal data it uploads to or generates within the Platform, that any notices required to be given to data subjects (including a privacy notice referencing Sabee as a processor) have been given, and that its instructions to Sabee comply with applicable data protection law. The Controller is responsible for the accuracy of personal data it enters into the Platform and for configuring access permissions appropriately within its own tenant.
6. Processor obligations (GDPR Article 28)
Sabee shall: process personal data only on documented instructions from the Controller, including with regard to international transfers, unless required to do otherwise by EU or Member State law, in which case Sabee shall inform the Controller of that legal requirement before processing, unless the law prohibits such notice; ensure persons authorised to process personal data are bound by confidentiality obligations; implement the technical and organisational measures described in Annex II; respect the conditions for engaging sub-processors described in Section 10; assist the Controller as described in Sections 11 and 13; notify the Controller of breaches as described in Section 12; make available information necessary to demonstrate compliance with this Article; and support the audit rights described in Section 16.
7. Controller instructions
Sabee shall process personal data only on documented instructions from the Controller. Those instructions are given by this DPA, the underlying subscription agreement, and the Controller's ordinary configuration and use of the Platform, including instructions given through in-app settings, support tickets and API calls. If Sabee believes an instruction infringes GDPR or another applicable data protection law, it shall inform the Controller without undue delay and may suspend performance of that specific instruction pending resolution.
8. Confidentiality
Sabee ensures that any person it authorises to process personal data under this DPA — including employees, contractors and sub-processor personnel — is subject to a binding written confidentiality obligation, whether contractual or statutory, and receives data-protection training appropriate to their role before being granted access.
9. Security measures
Sabee implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects. The full, current list of measures is set out in Annex II below, and a narrative summary is published on our security page. Sabee reviews these measures at least annually and following any material change to the Platform's architecture.
10. Sub-processors
The Controller provides a general authorisation for Sabee to engage the sub-processors listed in Annex III to assist in delivering the Platform. Sabee gives the Controller at least 30 days' written notice (by email to the tenant's registered administrator, or by posting an update to this page with a change note) before engaging a new sub-processor or replacing an existing one. The Controller may object on reasonable data-protection grounds within that 30-day window; if Sabee cannot address the objection through an alternative arrangement, the Controller may terminate the affected Subscription without penalty as its sole remedy. Sabee remains fully liable to the Controller for the acts and omissions of its sub-processors as if they were Sabee's own.
11. Assistance with data subject requests
Taking into account the nature of the processing, Sabee shall assist the Controller, insofar as possible, through appropriate technical and organisational measures, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights of access, rectification, erasure, restriction, portability and objection under GDPR Chapter III. Where the Platform's self-service tools (export, search, deletion within a tenant) do not fully satisfy a request, Sabee provides additional support through support@sabee.esesun.com within five business days of a documented request from the Controller.
12. Personal data breach notification
Sabee shall notify the Controller of any personal data breach affecting the Controller's data without undue delay after becoming aware of it, and in any event within 24 hours, using the emergency contact registered on the Controller's account. The notification includes, to the extent then known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach, with further detail provided as the investigation progresses. This 24-hour internal target is stricter than, and does not replace, the Controller's own statutory 72-hour notification obligation to its supervisory authority under GDPR Article 33.
13. DPIA and prior-consultation assistance
Sabee shall provide the Controller with reasonable assistance, taking into account the nature of processing and information available to Sabee, in carrying out data protection impact assessments under GDPR Article 35 and, where required, in any consultation with a supervisory authority under Article 36, including by providing relevant documentation regarding the security measures in Annex II and the categories of processing described in this DPA.
14. International transfers
Sabee's primary infrastructure hosting guest personal data is located within the European Union (AWS Frankfurt region). Where a sub-processor listed in Annex III is located outside the EU/EEA, any transfer of personal data to that sub-processor is governed by the European Commission's Standard Contractual Clauses (Module 2 or Module 3, as applicable), together with any supplementary technical and organisational measures identified as necessary in Sabee's transfer impact assessment. Sabee will not transfer personal data processed under this DPA to a jurisdiction without an adequacy decision except under such safeguards, and will notify the Controller of any new transfer arrangement as part of the sub-processor notice process in Section 10.
15. Return and deletion of data
Following termination or expiry of the subscription, the Controller has 30 days to retrieve Customer Data via the Platform's export tools or by request to support@sabee.esesun.com. After that 30-day retrieval window, Sabee proceeds to delete Customer Data, including guest personal data, from production systems and, following the normal backup rotation cycle, from backup media, completing full deletion within 90 days of termination, unless a longer retention period is required by applicable law or agreed in writing with the Controller. On written request, Sabee will provide confirmation that deletion has been completed.
16. Audit rights
The Controller may audit Sabee's compliance with this DPA once in any twelve-month period on 30 days' written notice, and additionally without the 30-day notice period following a personal data breach affecting the Controller's data. Audits are conducted during Sabee's normal business hours, in a manner that minimises disruption, and are subject to reasonable confidentiality protections. Sabee may satisfy an audit request by providing the Controller with the most recent independent third-party audit report available (such as a SOC 2 report, ISO 27001 certificate, or summary penetration-test findings) under non-disclosure, where that report reasonably addresses the scope of the Controller's request.
17. Liability
Liability arising out of or in connection with this DPA is subject to the limitation of liability set out in Section 14 of the Terms of Service, which applies to this DPA as if fully restated here, save that nothing in this DPA limits liability for a party's own regulatory fines imposed directly on it by a supervisory authority for its own independent breach of GDPR.
18. Term
This DPA takes effect on the date the Controller first accepts the Terms of Service or signs an order form, and remains in effect for as long as Sabee processes personal data on the Controller's behalf, including during the retrieval and deletion period described in Section 15, notwithstanding termination of the underlying subscription.
19. Governing law
This DPA is governed by the laws of the Republic of Estonia, consistent with Section 20 of the Terms of Service, and disputes arising under it are subject to the same dispute-resolution provisions set out there.
20. Contact
Questions about this DPA, or requests to execute a separately signed copy for internal record-keeping, should be sent to legal@sabee.esesun.com. Data protection matters specifically can also be directed to privacy@sabee.esesun.com.
Annex I — Processing details
| Item | Detail |
|---|---|
| Subject-matter | Provision of the Sabee hotel and hostel management platform |
| Duration | Term of the subscription plus the retrieval and deletion period in Section 15 |
| Nature of processing | Collection, storage, organisation, retrieval, transmission, restriction and deletion by automated means |
| Purpose of processing | Delivery of reservation management, channel management, booking engine, revenue analytics, accounting, housekeeping, guest CRM and multi-property services described in Section 2 |
| Types of personal data | As described in Section 3 |
| Categories of data subjects | As described in Section 4 |
| Controller obligations and rights | As described throughout this DPA, in particular Sections 5, 11 and 16 |
Annex II — Technical and organisational measures
Sabee maintains the following technical and organisational measures, reviewed at least annually:
- AES-256 encryption of personal data at rest
- TLS 1.3 encryption of personal data in transit
- Role-based access control aligned to job function
- Mandatory multi-factor authentication for administrative and privileged accounts
- Principle of least privilege applied to internal systems access
- Network segmentation isolating production data from staging and development environments
- Centralised logging and monitoring of access to production systems
- Automated alerting on anomalous access patterns
- Annual external penetration testing by an independent security firm
- Continuous automated vulnerability scanning of production infrastructure
- Encrypted, geographically redundant backups
- Quarterly restore testing of backup integrity
- Documented incident-response plan with defined escalation paths
- Background checks for employees with access to production personal data, where locally permitted
- Mandatory data-protection and security training at onboarding and annually thereafter
- Formal change-management process for production deployments
- Physical security controls at all data centre facilities, managed by our infrastructure host
- Data minimisation by design in new feature development
- Pseudonymisation of telemetry data where consistent with the purpose of processing
- Secure software development lifecycle including mandatory code review and automated security scanning
- Access revocation within 24 hours of employee offboarding
- Segregation of duties between engineering, security and customer support functions for sensitive operations
Annex III — Sub-processors
| Sub-processor | Role | Location |
|---|---|---|
| AWS (Amazon Web Services), Frankfurt region | Primary infrastructure hosting | European Union |
| Cloudflare | CDN, DNS and DDoS protection | EU edge network / global |
| Stripe | Payment processing and tokenisation | EU / United States (SCC-covered) |
| Postmark | Transactional email delivery | United States (SCC-covered) |
| Zendesk | Customer support ticketing | European Union |
| Fathom Analytics | Privacy-respecting aggregated analytics | European Union |
| Twilio | SMS notifications and verification | United States (SCC-covered) |
| HubSpot | Customer communications and CRM | European Union |
| Datadog | Application performance monitoring | United States / EU region (SCC-covered) |
| Loggly | Centralised log aggregation | United States (SCC-covered) |
| Sentry | Error tracking and crash diagnostics | United States / EU region (SCC-covered) |
| Segment | Internal event routing between systems | United States (SCC-covered) |
v3.2 Last updated 15 May 2026.